VYPR

Express Handlebars

by Express Handlebars Project

CVEs (2)

  • CVE-2021-32820HigMay 14, 2021
    risk 0.50cvss 8.6epss 0.18

    Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream…

  • CVE-2021-32817MedMay 14, 2021
    risk 0.28cvss 5.4epss 0.01

    express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This…

VYPR — Vulnerability Intelligence